CVE-2002-1292
Microsoft Java Virtual Machine <= 5.0.3805 - Denial of Service via Security Manager Bypass
Title source: llmDescription
The Microsoft Java virtual machine (VM) build 5.0.3805 and earlier, as used in Internet Explorer, allows remote attackers to extend the Standard Security Manager (SSM) class (com.ms.security.StandardSecurityManager) and bypass intended StandardSecurityManager restrictions by modifying the (1) deniedDefinitionPackages or (2) deniedAccessPackages settings, causing a denial of service by adding Java applets to the list of applets that are prevented from running.
References (6)
Core 6
Core References
Third Party Advisory, VDB Entry vdb-entry
x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/10585
Vendor Advisory vendor-advisory
x_refsource_ms
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2002/ms02-069
Third Party Advisory, VDB Entry vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/6133
Mailing List mailing-list
x_refsource_ntbugtraq
http://marc.info/?l=ntbugtraq&m=103684360031565&w=2
US Government Resource third-party-advisory
x_refsource_cert-vn
http://www.kb.cert.org/vuls/id/237777
Mailing List mailing-list
x_refsource_bugtraq
http://marc.info/?l=bugtraq&m=103682630823080&w=2
Scores
EPSS
0.2245
EPSS Percentile
97.5%
Details
Status
published
Products (1)
microsoft/java_virtual_machine
1.1
Published
Nov 29, 2002
Tracked Since
Feb 18, 2026